CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security
A Mumbai company's employee finds her files unreadable and a message demanding payment in cryptocurrency for a decryption key. Investigation shows she opened an attachment sent by an unknown sender, and the company had no offline backups. Which statement is most accurate?
It is a ransomware attack, a category of malware delivered through a malicious attachment. It encrypts files and demands payment for the key. Regularly tested offline backups are the main control, letting the company restore data without paying, unlike spyware, which silently collects information.
- AIt is a ransomware attack and a type of malware; maintaining tested offline backups is the key control that reduces dependence on paying the ransomCorrect
- BIt is a spyware attack, since the files were silently copied to the attacker without being encrypted
- CIt is a logic bomb, since the damage occurred on a date triggered by the employee
- DIt is a pharming attack, since the attachment redirected her to a fake website
Explanation
Encrypting files and demanding payment for a key is ransomware, a form of malware usually delivered through phishing attachments. Tested offline backups let the firm restore without paying. Spyware works covertly and does not lock files, so it does not fit.
Did you get it right without looking?
One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.
More Cyber Security questions
- Under the Information Technology Act, 2000, which authority serves as the national agency for performing functions in the area of cyber secu…
- Sahyadri Pharma Ltd wants a certifiable management system for protecting the confidentiality, integrity and availability of its information …
- Which provision of the Information Technology Act, 2000 designates CERT-In as the national agency for cyber security functions such as colle…
- A company secretary is asked to preserve a suspect laptop for a possible internal fraud investigation. Which first step best protects the ev…
- In the NIST Cybersecurity Framework (version 1.1), which set of five core functions is correctly listed?
- A forensic examiner computes a hash value of a seized pen drive at the time of seizure and again before producing it in court. The two hash …